Input validation vulnerability in Phlox Shop 2.0.0

The Phlox Shop plugin for WordPress is not secure in versions up to 2.0.0. Unauthenticated attackers can include and deploy any type of file on the server, including PHP, which could be used to get around security measures, access private information, or even execute code. This is possible because images and other “safe” file types can be uploaded and included.

Detected in:

Phlox Shop open vulnerable versions: >= * <= 2.0.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.